BEA WebLogic Vulnerabilities and new updates
N-Stalker has made available the latest database update for its Web Application Security Assessment Products. Following the support life-cycle, we are still distributing updates for previous version.
You will be able to download it automatically in the following versions:
- N-Stalker Web Application Security Scanner 2006 (Enterprise, QA and Infrastructure Edition)
- WSI Update (N-Stalker Update Manager)
- N-Stealth HTTP Security Scanner (database update 179)
- Automatic DB Update
You should be able to receive it automatically next time you execute the scanner.
If you prefer to download it manually, please, use the following url: https://customer.nstalker.com.
If you need any additional assistance during this process, please, contact us at:
Web: Open new support ticket at https://customer.nstalker.com
E-mail: http://www.nstalker.com/about/contact (24hs) or
Phone: +55-11-3675-7093 (9am to 18pm GMT-0300)
This release has included the following vulnerabilities:
- CuteNews 1.4.1 Show_News.PHP Cross-Site Scripting Vulnerability
- RunCMS 1.2 PMLite.PHP SQL Injection Vulnerability
- V-webmail 1.6.2 Multiple Cross-Site Scripting Vulnerabilities
- Gallery 1.5.2 Data Code Execution Vulnerability
- MyBB 1.03 Managegroup.PHP Cross-Site Scripting Vulnerability
- PHPNuke 7.7 Modules.PHP SQL Injection Vulnerability
- MyBB 1.03 Managegroup.PHP SQL Injection Vulnerability
- MyBB 1.03 Private.PHP Multiple SQL Injection Vulnerabilities
- QwikiWiki 1.5 Search.PHP Cross-Site Scripting Vulnerability
- CALimba 0.99.2 RB_auth.PHP Multiple SQL Injection Vulnerabilities
- E107 Website System 0.6171 BBCode HTML Injection Vulnerability
- sNews Multiple Input Validation Vulnerabilities
- PHPNuke Header.PHP 7.8 Pagetitle Parameter Cross-Site Scripting Vulnerability
- IPB Army System 2.1 Army.PHP SQL Injection Vulnerability
- Clever Copy 2.0a Multiple HTML Injection Vulnerabilities
- DocMGR 0.54.2 Process.PHP Remote File Include Vulnerability
- XMB Forum 1.9.3 Multiple Input Validation Vulnerabilities
- Lawrence Osiris DB_eSession Class 1.0.2 SQL Injection Vulnerability
- PHP Event Calendar 1.5 HTML Injection Vulnerability
- ELOG Web Logbook 2.6.1 Multiple Remote Vulnerabilities
- ELOG 2.6.0 Web Logbook Multiple Remote Input Validation Vulnerabilities
- Invision Power Board Portal Plugin 1.3 Index.PHP SQL Injection Vulnerability
- Mantis 1.0 Config_Defaults_Inc.PHP Cross-Site Scripting Vulnerability
- Webeveyn Whomp! Real Estate Manager Login SQL Injection Vulnerability
- CRE Loaded 6.15 Files.PHP Access Validation Vulnerability
- MyBB 1.02 Signature HTML Injection Vulnerability
- CheesyBlog 1.0 Multiple HTML Injection Vulnerabilities
- MyBB 1.0.2 Notepad UserCP.PHP HTML Injection Vulnerability
- MiniGal MG2 0.5.1 Image Gallery Name Field HTML Injection Vulnerability
- BEA WebLogic for Win32 8.1 SP5 Multiple Vulnerabilities
- Zoph 0.4pre2 Unspecified SQL Injection Vulnerability
- Pixelpost 1.4.3 User Comment HTML Injection Vulnerability
- vBulletin 3.5.2 Showthread.PHP Input Validation Vulnerability
- PHPBB 2.0.19 HTTP Referer Information Disclosure Vulnerability
- OpenSSL 0.9.7j/0.9.8b RSA Signature Forgery Vulnerability